Analytics Alerts
Browse the Cortex analytics alert reference.
2 alerts match the current filters. tactic: TA0007 ✕ technique: T1069 ✕
Download CSV Show ATT&CK heatmapLocal group enumeration Informational Identity Analytics 2 variations
A user performed an enumeration on local groups to retrieve their details.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- 5 Minutes
- Deduplication:
- 1 Day
ATT&CK tactics: Discovery (TA0007)ATT&CK techniques: Permission Groups Discovery: Local Groups (T1069.001) Permission Groups Discovery (T1069)Required data: Windows Event Collector XDR Agent with eXtended Threat Hunting (XTH)Attacker's goals: An adversary may leverage local groups discovery to identify privileged groups and escalate privileges.Investigative actions: Determine the user, hostname, and process that performed the group enumeration. Inspect process, command-line arguments or scripts used. Check for any privilege escalation or lateral movement attempts from the source system. Check if the tool used to enumerate the local groups is a known or an approved tool. Review the logs for suspicious activity from the same host or user.Variations
Local group enumeration for the first time
Low overridden
A user performed an enumeration on local groups to retrieve their details. overridden
Local group enumeration using a builtin Windows binary
Informational overridden
A user performed an enumeration on local groups to retrieve their details. overridden
Local group enumeration via RPC Informational 1 variation
A user enumerated local groups via RPC.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Discovery (TA0007)ATT&CK techniques: Permission Groups Discovery: Local Groups (T1069.001) Permission Groups Discovery (T1069)Required data: XDR Agent with eXtended Threat Hunting (XTH)Attacker's goals: An adversary may leverage local groups discovery to identify privileged groups and escalate privileges.Investigative actions: Determine the user, hostname, and process that performed the group enumeration. Inspect process, command-line arguments or scripts used. Check for any privilege escalation or lateral movement attempts from the source system. Check if the tool used to enumerate the local groups is a known or an approved tool. Review the logs for suspicious activity from the same host or user.Variations
Remote local group enumeration via RPC
Informational overridden
A user enumerated local groups via RPC. overridden